Skip to main content

Vendor archive

zohocorp CVEs

Beta · best-effort

550 CVEs tagged to vendor zohocorp143 Critical, 196 High, 201 Medium, 10 Low, 0 Unrated.

CVE-2024-27311

Published Jul 17, 2024

Zohocorp ManageEngine DDI Central versions 4001 and prior were vulnerable to directory traversal vulnerability which allows the user to upload new files to the server folder.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-27313

Published May 29, 2024

Zoho ManageEngine PAM360 is vulnerable to Stored XSS vulnerability. This vulnerability is applicable only in the version 6610.

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-36036

Published May 27, 2024

Zoho ManageEngine ADAudit Plus versions 7260 and below allows unauthorized local agent machine users to access sensitive information and modifying the agent configuration.

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-21791

Published May 22, 2024

Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL Injection in lockout history option. Note: Non-admin users cannot exploit this vulnerability.

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-27312

Published May 20, 2024

Zohocorp ManageEngine PAM360 version 6601 is vulnerable to authorization vulnerability which allows a low-privileged user to perform admin actions. Note: This vulnerability affec…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-0269

Published Feb 2, 2024

ManageEngine ADAudit Plus versions 7270 and below are vulnerable to the Authenticated SQL injection in File-Summary DrillDown. This issue has been fixed and released in version 72…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2024-0252

Published Jan 11, 2024

ManageEngine ADSelfService Plus versions 6401 and below are vulnerable to the remote code execution due to the improper handling in the load balancer component. Authentication is…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-47211

Published Jan 8, 2024

A directory traversal vulnerability exists in the uploadMib functionality of ManageEngine OpManager 12.7.258. A specially crafted HTTP request can lead to arbitrary file creation.…

CVSS 9.1 · Critical
Showing 76-100 of 550 CVEsPage 4 of 22